Paraben Forensics - P2 eXplorer v2.0
“…
Paraben's P2 eXplorer allows you to mount your forensic image and explore it as though it were a drive on your machine while preserving the forensic nature of your evidence. In fact, P2 eXplorer is one of the only programs that mounts images as logical and physical disks. This means all the deleted, slack, and unallocated space is accessible. An image isn't just mounted to view logical files; it is mounted as an actual bit-stream image, preserving unallocated, slack, and deleted data. P2X is easy to use and most importantly, it's free to registered users.
FEATURES:
- Mounts images as physical disks
- Mounts Paraben's Forensic Replicator images (PFR)
- Mounts compressed & encrypted PFR images
- Mounts EnCase images (up to v6)
- Mounts SafeBack 1, 2 and 3 images
- Mounts SMART images
- Mounts FTK DD and Encase images
- Mounts WinImage non-compressed images
- Mounts RAW images from Linux DD & other tools
- Supports Dynamic drive images
- Auto-detects image format
- Supports both logical and physical images types
- …
…”
Not a utility you might usually see me mention, but it’s one of those, if you need it you need it (and I know I’ll need this in the future… so… ;)
(via EDD Update - Free E-Discovery Tools that May Be Worth a Bundle)
No comments:
Post a Comment
NOTE: Anonymous Commenting has been turned off for a while... The comment spammers are just killing me...
ALL comments are moderated. I will review every comment before it will appear on the blog.
Your comment WILL NOT APPEAR UNTIL I approve it. This may take some hours...
I reserve, and will use, the right to not approve ANY comment for ANY reason. I will not usually, but if it's off topic, spam (or even close to spam-like), inflammatory, mean, etc, etc, well... then...
Please see my comment policy for more information if you are interested.
Thanks,
Greg
PS. I am proactively moderating comments. Your comment WILL NOT APPEAR UNTIL I approve it. This may take some hours...